Microsoft Sentinel solution for SAP® applications

Solution: SAP

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Solutions Index


Attribute Value
Publisher
Support Tier
Last Updated 2026-06-03
Solution Folder SAP
Marketplace Azure Marketplace · Rating: ★★★★☆ 4.3/5 (3 ratings) · Popularity: 🟢 High (91%)

Microsoft Sentinel solution for SAP® applications

Contents

Data Connectors

This solution provides 2 data connector(s):

🔶 CLv1: This connector ingests into a table that uses the legacy Custom Log V1 schema format with type-suffixed column names (e.g. _s, _d, _b, _t, _g). Note: identification is based on column name suffixes which are also permitted in CLv2, so this classification may not always be accurate.

Tables Used

This solution uses 8 table(s):

Table Used By Connectors Used By Content
ABAPAuditLog Microsoft Sentinel for SAP applications - agentless -
ABAPAuditLog_CL 🔶 Microsoft Sentinel for SAP -
ABAPAuthorizationDetails Microsoft Sentinel for SAP applications - agentless -
ABAPAuthorizationDetails_CL 🔶 Microsoft Sentinel for SAP -
ABAPChangeDocsLog Microsoft Sentinel for SAP applications - agentless -
ABAPChangeDocsLog_CL 🔶 Microsoft Sentinel for SAP -
ABAPUserDetails Microsoft Sentinel for SAP applications - agentless -
ABAPUserDetails_CL 🔶 Microsoft Sentinel for SAP -

🔶 CLv1: This table uses the legacy Custom Log V1 schema format with type-suffixed column names (e.g. _s, _d, _b, _t, _g). Note: identification is based on column name suffixes which are also permitted in CLv2, so this classification may not always be accurate.

Content Items

This solution includes 3 content item(s) (0 in solution, 3 discovered 🔍):

Content Type Total In Solution Discovered
Playbooks 3 0 3

Playbooks

Name Description Tables Used
SAP - Lock User (Agentless Basic) ⚠️ This playbook locks an SAP user when triggered by a Microsoft Sentinel incident. It dynamically find... -
workflow ⚠️ < 🏡home -
workflow ⚠️ < 🏡home -

⚠️ Items marked with ⚠️ are not listed in the Solution JSON file. They were discovered by scanning the solution folder and may be legacy items, under development, or excluded from the official solution package.

Additional Documentation

📄 Source: SAP/README.md

Microsoft Sentinel solution for SAP ERP and S/4HANA using the agentless data connector leveraging SAP Integration Suite.

For more information, see the Microsoft Sentinel solution for SAP applications.

For the current release notes and version history of the solution package component on SAP Integration Suite, see Agentless Release Notes.

For the current release notes and version history of the overall Microsoft Sentinel solution for SAP applications, see Release Notes.

For related automation and response content, see the SAP playbooks.

Release Notes

Solution Release Notes

[!NOTE] The legacy SAP agent-based connector reached end of life on 14-09-2026. See the migration guide for details.

For the current release notes and version history of the agentless package on SAP Integration Suite, see Agentless SAP README.

Version Date Modified (DD-MM-YYYY) Change History
3.5.10 30-06-2026 Removal of Agent-based connector from solution. Zip file link redirected to SAP Business Accelerator Hub (moved from editable to configure-only release).

Prior version history (since 2023) for Agent-based connector compacted.


Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Solutions Index